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Arguments 

Claims 1-6,9, 10, 13 and 17 stand rejected under 35 U.S.C. § 103(a) as being 
unpatentable over Hursey et al. (US Pub. No, 2003/0074573) ("Hursey") in view of Desai 
(US Pub. No. 2003/0188189). 

The rejection is respectfully traversed As to independent claim 1, Hursey and 
Desai do not support the rejection for at least the reason that, to even in combination, they 
fail to disclose or suggest "a normalization module that obtains an executable script and 
generates a normalized signature for the executable script, wherein generating a 
normalized signature for the executable script comprises translating tokens from the 
executable script into normalized tokens conforming to a common format," as recited in 
claim 1. 

The Office Action correctly recognizes that Hursey is deficient as to the noted 
features, but cites Desai for the disclosure absent &pm Hursey. However, Desai is 
likewise deficient 

In more detail, the Office Action cites paragraphs [0051] and [0052] of Desai in 
support of the rejection. However, these paragraphs do not describe translating tokens 
from the executable script into normalized tokens conforming to a common format, as 
recited in claim 1 . Instead, they describe formatting an event log. Clearly, an event log 
is not an executable script as recited in claim 1 . Accordingly, claim 1 is allowable over 
Hursey and Desai. 

Independent claims 3, 4 and 5 include similar recitations to those of claim 1 noted 
above, and are consequently likewise allowable over Hursey and Desai. 

Prorosed new claims 

21. (New) A computing device configured with a process to detect malware, the 
process including: 
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parsing an executable script to obtain a plurality of tokens therefrom, the plurality 

of tokens including tokens respectively corresponding to variables and subroutines of the 
executable script; 

if a token of the plurality of tokens obtained corresponds to a variable, generating 
a variable token based on renaming die variable; 

if a token of the plurality of tokens obtained corresponds to a subroutine, 
generating a subroutine token based on renaming the subroutine; 

forming a token set from the variable token and the subroutine token; 

comparing the token set with a token set of a known malware script; and 

if there is a match, reporting that the executable script is malware. 

22. (New) The computing device of claim 21, the parsing further including 
obtaining tokens respectively corresponding to operators, constants, execution directives, 
comments and white space. 
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